Volume

Block object storage hosted on-premise or by third-party providers, typically made available to resources as virtualized hard drives[1][2][3]

ID: DS0034
Platforms: IaaS, Linux, Windows, macOS
Collection Layers: Cloud Control Plane, Host
Contributors: Center for Threat-Informed Defense (CTID)
Version: 1.0
Created: 20 October 2021
Last Modified: 10 November 2021

Data Components

Volume: Volume Creation

Initial construction of a cloud volume (ex: AWS create-volume)

Volume: Volume Creation

Initial construction of a cloud volume (ex: AWS create-volume)

Domain ID Name
Enterprise T1578 Modify Cloud Compute Infrastructure

Volume: Volume Deletion

Removal of a a cloud volume (ex: AWS delete-volume)

Volume: Volume Deletion

Removal of a a cloud volume (ex: AWS delete-volume)

Domain ID Name
Enterprise T1485 Data Destruction
Enterprise T1578 Modify Cloud Compute Infrastructure

Volume: Volume Enumeration

An extracted list of available volumes within a cloud environment (ex: AWS describe-volumes)

Volume: Volume Enumeration

An extracted list of available volumes within a cloud environment (ex: AWS describe-volumes)

Domain ID Name
Enterprise T1580 Cloud Infrastructure Discovery

Volume: Volume Metadata

Contextual data about a cloud volume and activity around it, such as id, type, state, and size

Volume: Volume Metadata

Contextual data about a cloud volume and activity around it, such as id, type, state, and size

Domain ID Name
Enterprise T1580 Cloud Infrastructure Discovery

Volume: Volume Modification

Changes made to a cloud volume, including its settings and control data (ex: AWS modify-volume)

Volume: Volume Modification

Changes made to a cloud volume, including its settings and control data (ex: AWS modify-volume)

Domain ID Name
Enterprise T1578 Modify Cloud Compute Infrastructure

References